BleepingComputer.com: MS05-016:VBS_RUNEXPLT.C (arrives as Word Document)

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

MS05-016:VBS_RUNEXPLT.C (arrives as Word Document)

#1 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

Posted 28 May 2005 - 03:54 PM

This new threat arrives as a Word document and manipuates unpatched Windows PCs, manipulating the recent MS05-016 patch which was part of the April 2005 updates provided by Microsoft.

MS05-016:VBS_RUNEXPLT.C (arrives as Word Document)
http://secunia.com/virus_information/18394/

This malicious VBScript file takes advantage of the Windows Shell vulnerability, which could allow a remote malicious user to execute arbitrary code on the affected system. For more information about this vulnerability, please refer to the following Microsoft page: Microsoft Security Bulletin MS05-016

It usually arrives on a system as a Microsoft Word document. When executed on a vulnerable machine, it attempts to download and execute a file, which may also be malicious in nature, from the following location: Nnpyf.c{BLOCKED}nn.com. This malicious VBScript file runs on Windows 98, ME, 2000, and XP.

April 2005 - Microsoft Security Bulletin MS05-016
http://www.microsoft.com/technet/security/...n/MS05-016.mspx

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users